Is hybrid: No
Is remote: No
Employer: Google
Minimum qualifications:
- Bachelor's degree or equivalent practical experience.
- 5 years of experience with security assessments or security design reviews or threat modeling.
- 5 years of experience as a technical security professional, with computer and network security and security protocols.
- Experience with executive or customer stakeholder management and communication.
- Experience with a data-driven approach towards solving information security challenges.
Preferred qualifications:
- Master's degree in Computer Science or a related field.
- Certification in Certified Information Systems Security Professional (CISSP) or similar Cyber Security/Incident Response.
- Experience analyzing, triaging, and remediating common information security incidents.
- Experience with automation via coding, scripting or large language models.
- Understanding of common attacker tactics, tools, and techniques.
- Excellent problem-solving, investigative, and written and verbal communication skills. Ability to work separately, prioritize, and multitask.
About the job
As a Security Analyst in the Vulnerability Coordination Center you will be responsible for ensuring threats posed by software and infrastructure vulnerabilities are resolved company wide. You will work with engineers, product teams or vulnerability coordinators on the analysis of, and response to vulnerabilities reported by other parties, internal and external. You will work to support the creation and ongoing support of tools, processes and guidelines that promote the continual management and reduction of vulnerability risk across the company.
The Core team builds the technical foundation behind Google’s flagship products. We are owners and advocates for the underlying design elements, developer platforms, product components, and infrastructure at Google. These are the essential building blocks for excellent, safe, and coherent experiences for our users and drive the pace of innovation for every developer. We look across Google’s products to build central solutions, break down technical barriers and strengthen existing systems. As the Core team, we have a mandate and a unique opportunity to impact important technical decisions across the company.
Responsibilities
- Establish and mature cross-company processes around vulnerability management including operating models, maturity models, Service Level Agreement (SLA)/Service Level Objectives (SLOs), discovery, managing and reporting processes, roles/responsibilities, etc.
- Coordinate resolution of issues cross-company that arise from vulnerabilities, working with internal and industry stakeholders to comprehensively remediate security risk.
- Work with industry partners in the vulnerability coordination space, including working groups, standards bodies, Common Vulnerabilities and Exposures issuance, etc.
- Ensure compliance with legal mandates and internal Security and Privacy policies.
- Automate security workflows and develop appropriate tooling and processes.
Google is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. See also
Google's EEO Policy and
EEO is the Law. If you have a disability or special need that requires accommodation, please let us know by completing our
Accommodations for Applicants form.